PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
PoC publicPhpSpreadsheetOur summary
A critical remote code execution issue tracked as CVE-2026-45034 has been disclosed in PhpSpreadsheet (PHPOffice), along with public proof-of-concept exploit details. The problem stems from a patch-bypass weakness in File::prohibitWrappers that attackers can evade by manipulating wrapper input, allowing dangerous file handling and, depending on the PHP version and application behavior, potential deserialization to reach RCE. Versions in the 1.x series up to 1.30.4 are reported as vulnerable, and upgrading to 1.30.5 is recommended to reduce exposure.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.